VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (23,177)

page 918 of 1,159
  • CVE-2018-16808Mar 7, 2019
    risk 0.00cvss epss 0.00

    An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.

  • CVE-2018-20244Feb 27, 2019
    risk 0.00cvss epss 0.01

    In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.

  • CVE-2019-9142Feb 25, 2019
    risk 0.00cvss epss 0.00

    An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.

  • CVE-2019-8331Feb 20, 2019
    risk 0.00cvss epss 0.02

    In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

  • CVE-2019-8400Feb 17, 2019
    risk 0.00cvss epss 0.00

    ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.

  • CVE-2018-20242Feb 11, 2019
    risk 0.00cvss epss 0.01

    A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.

  • CVE-2018-20757Feb 6, 2019
    risk 0.00cvss epss 0.00

    MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.

  • CVE-2018-20755Feb 6, 2019
    risk 0.00cvss epss 0.00

    MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.

  • CVE-2018-20756Feb 6, 2019
    risk 0.00cvss epss 0.00

    MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.

  • CVE-2018-20758Feb 6, 2019
    risk 0.00cvss epss 0.00

    MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.

  • CVE-2019-1003014Feb 6, 2019
    risk 0.00cvss epss 0.00

    An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user…

  • CVE-2019-1003013Feb 6, 2019
    risk 0.00cvss epss 0.00

    An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfig.java,…

  • CVE-2019-1003023Feb 6, 2019
    risk 0.00cvss epss 0.00

    A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis/core/model/DetailsTableModel.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourceDetail.java,…

  • CVE-2018-16484Feb 1, 2019
    risk 0.00cvss epss 0.00

    A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names.

  • CVE-2018-16481Feb 1, 2019
    risk 0.00cvss epss 0.00

    A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.

  • CVE-2018-16480Feb 1, 2019
    risk 0.00cvss epss 0.00

    A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due to the absence of sanitization of the file/folder names before rendering.

  • CVE-2019-7171Jan 29, 2019
    risk 0.00cvss epss 0.00

    A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/blocks/blocks/edit/8.

  • CVE-2019-7170Jan 29, 2019
    risk 0.00cvss epss 0.00

    A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/taxonomy/vocabularies.

  • CVE-2019-7173Jan 29, 2019
    risk 0.00cvss epss 0.00

    A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4.

  • CVE-2019-7168Jan 29, 2019
    risk 0.00cvss epss 0.00

    A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Blog field to /admin/nodes/nodes/add/blog.